fix(09): WR-11 reject ambiguous admin logins and cross-field login or email collisions
This commit is contained in:
@@ -69,7 +69,10 @@ func adminCreate(ctx context.Context, app *backpack.App, in bonfire.Input, out b
|
||||
return err
|
||||
}
|
||||
var existing int64
|
||||
if err := tx.Model(&BackendUser{}).Where("login = ? OR lower(email) = ?", login, email).Count(&existing).Error; err != nil {
|
||||
// Check both fields against both values: a new login equal to an
|
||||
// existing email (or the reverse) would make the login identifier
|
||||
// ambiguous, so neither admin could rely on it.
|
||||
if err := tx.Model(&BackendUser{}).Where("login IN (?, ?) OR lower(email) IN (?, ?)", login, email, strings.ToLower(login), email).Count(&existing).Error; err != nil {
|
||||
return err
|
||||
}
|
||||
if existing > 0 {
|
||||
|
||||
Reference in New Issue
Block a user